pub fn run_sumcheck<F, P: PackedField<Scalar = F>, Channel: IPProverChannel<F>, A: Allocator>(
public_folded: &FieldVec<P, A>,
hidden_folded: FieldVec<P, A>,
public_monster: &FieldVec<P, A>,
hidden_monster: FieldVec<P, A>,
shift_ind_eval: F,
public_words: &[Word],
r_j: Vec<F>,
gamma: F,
channel: &mut Channel,
alloc: &A,
) -> ShiftOutput<F>where
F: BinaryField,Expand description
Executes the phase-2 sumcheck over the witness, with a sparse first round.
§Overview
The witness and the constraint-matrix multilinear are each given as a (public, hidden) segment pair. The top word-index variable selects the segment.
The first round binds that selector without materializing the mostly-zero combined buffers. After the selector challenge, the segment pairs fold into single dense buffers, and a shared dense-product prover proves the remaining rounds. So every round message is identical to what a fully dense prover would send.
After the sumcheck, this derives the witness evaluation from the combined evaluation: it evaluates the public segment directly (cheap, like the verifier does), subtracts its padded contribution, and scales.
It also divides the three bit-index factors back out of the constraint-matrix evaluation, leaving the wiring evaluation the verifier’s claim is about.
§Returns
The sumcheck’s concatenated challenges with the witness evaluation, and the wiring evaluation for the caller to send.